Install
$ agentstack add skill-jschuller-mcp-server-servicenow-triaging-incidents ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Triaging ServiceNow Incidents
Create, triage, investigate, and analyze incidents. See references/incident-fields.md for the priority matrix, states, categories, and encoded query patterns.
Workflows
1. List Recent Incidents
Get a summary of recent incidents by priority, state, or assignment group.
Progress checklist (copy into your response):
- [ ] Query incidents with filters
- [ ] Summarize by priority and state
- [ ] Highlight critical/P1 incidents
- List recent incidents (last 24 hours, open):
`` list_records(table_name="incident", query="active=true^sys_created_on>=javascript:gs.daysAgoStart(1)", fields="number,short_description,priority,state,assignment_group,assigned_to,sys_created_on", limit=20, order_by="-priority") ``
- For a specific assignment group:
`` list_records(table_name="incident", query="active=true^assignment_groupLIKE", fields="number,short_description,priority,state,assigned_to", limit=20) ``
- Summarize: total count, breakdown by priority (P1/P2/P3/P4), breakdown by state, highlight any P1/P2 incidents.
2. Triage a New Incident
Assess impact and urgency, then suggest priority, category, and assignment group.
Progress checklist:
- [ ] Get incident details
- [ ] Assess impact and urgency
- [ ] Check affected CI and its dependencies
- [ ] Suggest priority, category, assignment group
- [ ] Recommend next steps
- Get the incident details:
`` get_record(table_name="incident", sys_id="") ``
- If a CI is attached, check its relationships to assess blast radius:
`` get_ci(sys_id="") get_ci_relationships(sys_id="") ``
- Look for similar recent incidents (same CI or category):
`` list_records(table_name="incident", query="cmdb_ci=^sys_created_on>=javascript:gs.daysAgoStart(30)", fields="number,short_description,state,priority", limit=10) ``
- Recommend triage decisions:
- Priority: Based on impact x urgency matrix (see
references/incident-fields.md) - Category: Based on the affected CI class and description keywords
- Assignment group: Based on CI ownership or category routing rules
- Present recommendations with reasoning.
3. Investigate an Incident
Deep-dive into an existing incident — full context, related CIs, similar incidents.
Progress checklist:
- [ ] Get full incident details
- [ ] Get affected CI details and relationships
- [ ] Find similar recent incidents
- [ ] Check for related problems or changes
- [ ] Summarize findings and recommend actions
- Get the full incident record:
`` get_record(table_name="incident", sys_id="") ``
- If a CI is attached, get its details and dependency chain:
`` get_ci(sys_id="") get_ci_relationships(sys_id="") ``
- Find similar recent incidents:
`` list_records(table_name="incident", query="categoryLIKE^sys_created_on>=javascript:gs.daysAgoStart(30)", fields="number,short_description,state,priority,resolution_notes", limit=10) ``
- Check for related problems:
`` list_records(table_name="problem", query="cmdb_ci=^active=true", fields="number,short_description,state", limit=5) ``
- Check for recent changes on the same CI:
`` list_records(table_name="change_request", query="cmdb_ci=^sys_created_on>=javascript:gs.daysAgoStart(7)", fields="number,short_description,state,type", limit=5) ``
- Summarize: incident context, CI dependency impact, related incidents/problems/changes, recommended actions.
4. Create an Incident
Create a new incident with validated fields and appropriate defaults.
Progress checklist:
- [ ] Validate required fields are provided
- [ ] Suggest category from description
- [ ] Set appropriate defaults (state, priority)
- [ ] Create the incident
- [ ] Confirm creation with INC number
- Validate required fields:
short_descriptionis mandatory. Confirmcaller_idis provided. - Suggest category based on description keywords (see
references/incident-fields.md). - Set defaults for missing fields:
state: 1 (New)impact: 3 (Low) unless specifiedurgency: 3 (Low) unless specifiedpriorityis auto-calculated from impact x urgency
- Create the incident:
`` create_record(table_name="incident", data={"short_description": "...", "description": "...", "caller_id": "...", "category": "...", "impact": "3", "urgency": "3", "cmdb_ci": "..."}) ``
- Confirm creation: return the INC number, priority, and link.
5. Bulk Analysis
Analyze incident trends — top categories, repeat offenders, SLA status.
Progress checklist:
- [ ] Pull recent incidents (7-30 day window)
- [ ] Group by category
- [ ] Identify repeat CIs (frequent flyers)
- [ ] Check SLA breaches
- [ ] Present trends and recommendations
- Pull recent incidents:
`` list_records(table_name="incident", query="sys_created_on>=javascript:gs.daysAgoStart(30)^active=true", fields="number,category,cmdb_ci,priority,state,assignment_group,sla_due", limit=100, order_by="-sys_created_on") ``
- Group by category — which categories generate the most incidents?
- Identify repeat CIs — which CIs appear in multiple incidents?
`` list_records(table_name="incident", query="cmdb_ci=^sys_created_on>=javascript:gs.daysAgoStart(30)", fields="number,short_description,priority,state", limit=20) ``
- Check for SLA breaches:
`` list_records(table_name="incident", query="active=true^sla_due", fields="name,sys_id").
- See
references/incident-fields.mdfor encoded query patterns and field reference.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jschuller
- Source: jschuller/mcp-server-servicenow
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.